Szegedy 2013 (imperceptible perturbations)
First adversarial examples for images. Established field. Perturbations that flip predictions.
Advertisement
Goodfellow 2014 (FGSM)
Fast Gradient Sign Method. Efficient adversarial example generation. Also introduced GANs.
Advertisement
Papernot 2016 (transferability)
Adversarial examples transfer across models. Black-box attacks possible.
Madry 2018 (PGD training)
Robust training via PGD. Standard adversarial defense.